CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.
CVE
CVE-2016-20011
Severity
HIGH
CVSS
7.5
EPSS
1.47%
Original NVD Description
libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.
Related CVEs
Other vulnerabilities affecting the same vendor(s)